generated: '2026-08-27' method: searched source: https://github.com/wger-project/wger/blob/master/SECURITY.md program: published: true kind: repository-security-policy url: https://github.com/wger-project/wger/blob/master/SECURITY.md bug_bounty: false platform: null safe_harbor: not stated disclosure_policy: not stated response_sla: >- "We will try to fix it as fast as we can" — no committed timeframe contact: - kind: email value: roland [at] geider.net note: >- Published obfuscated in the policy; reproduced here in the same obfuscated form the project uses. - kind: github value: mention @rolandgeider in an issue url: https://github.com/wger-project/wger/issues supported_versions: policy: latest release only statement: >- "While we do have versions and releases, wger is developed and deployed like a rolling release. Currently we don't have the resources to support older versions." probes: - url: https://wger.de/.well-known/security.txt status: 404 checked: '2026-08-27' - url: https://github.com/wger-project/wger/blob/master/SECURITY.md status: 200 checked: '2026-08-27' result: policy found - url: https://hackerone.com/wger status: not probed note: >- SECURITY.md names email and a GitHub mention as the only two channels; no bounty platform is referenced anywhere on the project's surfaces. gaps: - >- No RFC 9116 security.txt at https://wger.de/.well-known/security.txt. The policy exists but is only discoverable from the GitHub repository, not from the running instance a researcher would actually be probing — the single highest-value, lowest-effort fix available to this project. - No safe-harbour statement and no disclosure timeline. - >- Reporting routes to one maintainer's personal email rather than a project-owned address or GitHub's private vulnerability reporting. note: >- probe-security-programs.py reported vdp=none because it looks for a served security.txt and for bounty-platform pages on the provider's own host, and wger serves neither. The policy is nonetheless real and published — it is in the source repository, which for an AGPL self-hosted project is the primary distribution surface. Recorded as searched on that evidence.